CVE-2008-1215 Information
Feb 14, 2021
cve
Description
Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp) as distributed in FreeBSD 6.3 and 7.0 OpenBSD 4.1 and 4.2 and the net/userppp package for NetBSD allows local users to gain privileges via long commands containing ~\ characters.
Reference
http://secunia.com/advisories/29234 http://secunia.com/advisories/29238 http://secunia.com/advisories/29240 http://www.openbsd.org/errata41.html014_ppp http://www.openbsd.org/errata42.html009_ppp http://www.securityfocus.com/archive/82/488980/30/0/threaded http://www.securityfocus.com/archive/82/489031/30/0/threaded http://www.securityfocus.com/bid/28090 https://exchange.xforce.ibmcloud.com/vulnerabilities/41034
Share on: